Security attack situation awareness based on massive log data mining

2022 5th International Conference on Advanced Electronic Materials, Computers and Software Engineering (AEMCSE)(2022)

引用 0|浏览0
暂无评分
摘要
Security situation awareness usually uses massive log information to discover abnormal attacks based on basic user attributes, user behavioral actions and user interactions through machine learning and other methods. Considering that the interaction between users in security situation awareness is exactly the graph data structure to which graph neural networks are applicable, this paper proposes a graph neural network-based security situation awareness method for massive logs, by mining log data, extracting user features for aggregation, and finally predicting user behavior to achieve security situation awareness. Compared with traditional supervised or unsupervised learning algorithms, the graph structure built in this paper not only retains the information carried by the users themselves, but also retains the relationship features between users and users, and between users and servers. By mapping the relationships between users to homogeneous graphs and between users and servers to heterogeneous graphs, and introducing an attention mechanism to dynamically adjust the weights of neighboring nodes, the accuracy of graph neural network learning can be effectively improved.
更多
查看译文
关键词
Graphical neural networks,security situation awareness,attention mechanisms,log analysis,data mining
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要